What is an initial-access broker?¶
The practical answer¶
An initial-access broker is a person or service that obtains access to organisations or systems and sells, transfers or provides that access to others.
The key evidential caution¶
The dangerous assumption is that the person who first gained access also carried out every later stage of the incident.
They may not have.
An access broker may provide:
Key points¶
- working credentials
- remote desktop access
- VPN access
- web-shell access
- cloud sessions
- administrator access
- details of exposed services
- persistence already installed
Investigators should distinguish:
- who obtained the access
- how it was obtained
- when it was sold or transferred
- who later used it
- what access level existed
- whether access was exclusive
- what communications or payment linked the parties
The same access may be sold more than once.
A later ransomware or fraud operator may use a foothold created by someone else.
Relevant evidence¶
Relevant evidence may include marketplace listings, chats, access credentials, login patterns, payment records, provider data, seized devices and changes in activity after transfer.
Evidential limits¶
Do not infer that matching access methods prove one continuous offender.
A broker may advertise access at one privilege level while the buyer later discovers something different. Preserve listings, screenshots, chats and any victim-specific details that show what was offered. The sale description should not be treated as proof of the actual access until technical records confirm it.
Access may also expire, be revoked or be resold after the listing. Compare the sale time with later authentication and session records to show whether the buyer actually used the offered foothold.
Operational takeaway¶
Separate creation, sale and later use of access, and attribute each role from communications, financial, account and technical evidence.